Impact
The vulnerability lies in the yshop‑crm application, where the saveRedisSet and getRedisSet endpoints in CrmCustomerController do not enforce authorization checks. This allows any authenticated back‑office user to read and modify shared Redis keys that control the system’s customer auto‑recycling policy and lead‑allocation behaviour. An attacker could, therefore, trigger mass deletion of customer records, disable lead recycling, or prevent new customer creation, resulting in significant integrity and availability damage.
Affected Systems
The affected product is yshop‑crm from the vendor guchengwuyue. All releases up to and including version 2.1.3 are vulnerable. No newer versions are listed as affected.
Risk and Exploitability
The CVSS score of 7.1 marks this as a high‑severity flaw. The EPSS score of less than 1% indicates a very low exploitation probability at the time of assessment, and the vulnerability is not listed in CISA KEV. The likely attack vector, inferred from the description, is an authenticated back‑office user executing the exposed endpoints without additional authorization. Successful exploitation would give the attacker the ability to manipulate critical business-configurable Redis keys, leading to destructive data loss or operational disruption.
OpenCVE Enrichment